Two of the three items from #54 (item 1, the dead is_return column, is
a drop-or-use product call left for mara — see issue comment):
1. The RFC7807 404 handler for /api and /admin/api was only registered
inside the 'if (existsSync(clientDist))' branch, so a server-only
deploy (or any run before 'pnpm --filter client build') fell through
to Fastify's default 404 shape instead — quietly opting API routes
out of the one-error-shape guarantee the RFC7807 conversion was for.
Split registration from the static-file serving: the not-found
handler (and its API-vs-SPA-fallback branching) is now unconditional,
only the SPA html sendFile calls stay gated on hasClientDist.
2. STATS_PUBLIC added to the README's env-var list (was only in
deploy/wutzcalc.env.example) — an operator wanting the infopoint-
screen setup wouldn't find the switch, and an operator auditing
"what can expose data here" from the README wouldn't see it exists.
Verified live: renamed client/dist away and confirmed /api, /admin/api,
and a bare unmatched route all return RFC7807 problem+json (no crash);
restored it and confirmed the SPA fallback (admin.html/stats.html/
index.html) still serves correctly. tsc --noEmit and server build both
clean.